QID 730840

Date Published: 2023-07-18

QID 730840: Jfrog Artifactory Weak Password Vulnerability

JFrog Artifactory is the only Universal Repository Manager supporting all major packaging formats, build tools and CI servers.

Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0.

Affected Versions:
JFrog Artifactory prior to 6.17

QID Detection Logic:(Unauthenticated)
This QID checks for the version of Artifactory on the target.

On successful exploitation it may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are suggested to upgrade to JFrog Artifactory 6.17 or later or later.
    Vendor References

    CVEs related to QID 730840

    Software Advisories
    Advisory ID Software Component Link
    JFrog Artifactory 6.17.0 URL Logo www.jfrog.com/confluence/display/RTF6X/Release+Notes#ReleaseNotes-Artifactory6.17.0